All Apps and Add-ons

Splunk Cloud app/add-ons installs & search heads

TimmL
Engager

Hello!

We are new to Splunk Cloud and have a question about installing app/add-ons that we couldn't find definitive information on in the documentation.

We have 3 instances, IDM, Search head 1, and Search head 2 which is our Enterprise Security (ES) instance.

Which one is the indexer? The IDM instance is a sort of Heavy forwarder correct?

When installing apps such as the 'Splunk Add-on for F5 BIG-IP' or the 'Cloudflare App for Splunk' the instructions say to install on the search head(s), Should they be installed on Both search heads? Or just one? What are the advantages or disadvantages of either?

Sorry for the barrage of questions but we are having trouble wrapping our head around how these instances all work together and how the apps interact.
Thanks!

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Your Splunk Cloud indexers are there, but are mostly hidden.  Of the three instances listed, none is an indexer since one of them is an IDM (similar to an HF) and the others are search heads.

When installing apps, just install them on the SH where they will be used.  Splunk Cloud will know which pieces of the app need to be on the indexers and will install them there as well.

Since ES can be a resource hog, only install an app on that search head if it needs to be used with ES.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Your Splunk Cloud indexers are there, but are mostly hidden.  Of the three instances listed, none is an indexer since one of them is an IDM (similar to an HF) and the others are search heads.

When installing apps, just install them on the SH where they will be used.  Splunk Cloud will know which pieces of the app need to be on the indexers and will install them there as well.

Since ES can be a resource hog, only install an app on that search head if it needs to be used with ES.

---
If this reply helps you, Karma would be appreciated.

TimmL
Engager

Great thank you thats exactly what we were looking for!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...